{"slug": "unsloths-model-picker-had-a-code-execution-problem", "title": "Unsloth’s model picker had a code-execution problem", "summary": "Pillar Security found that selecting a model in Unsloth Studio triggered the download and execution of Python code from the model repository, with researcher Ariel Fogel stating \"Reading the model's config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference.\" Unsloth fixed the flaw in June and shipped the change in version 2026.6.9, which no longer enables arbitrary model loading directly from Hugging Face or trusts remote code from local model files, but its maintainers declined to publish a security advisory or have a CVE assigned, citing Studio's beta status — a rationale Pillar contests because the vulnerable code ships in the generally available \"unsloth\" package on PyPI via \"pip install unsloth\".", "body_md": "True to its name, AI-model-training tool [Unsloth](https://www.infoworld.com/article/4211593/hands-on-with-unsloth-desktop-for-running-and-training-llms-locally.html) would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines.\n\nPillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a specially crafted model to get malicious code executed on a developer’s system.\n\n“The code ran from nothing more than a metadata check,” researcher [Ariel Fogel](https://www.linkedin.com/in/arielfogel) said in a [post on Pillar’s blog](https://www.pillar.security/blog/look-dont-load-model-inspection-in-unsloth-studio-leads-to-critical-arbitrary-code-execution). “Reading the model’s config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference.”\n\nThe code would run with the user’s permission which, Fogel said, could expose proprietary training data, model artifacts, Hugging Face tokens, SSH keys, or accessible cloud credentials in an enterprise’s AI development environment.\n\nUnsloth Studio is a web-based interface that is currently in beta, a status Unsloth’s maintainers cited when they reportedly declined to publish a security advisory or have a CVE assigned to the flaw after [fixing it in June](https://unsloth.ai/docs/new/changelog#id-2026-05-26). Pillar contests that reasoning, pointing out that the vulnerable Studio code ships as part of the standard, generally available “unsloth” package on [PyPI](https://www.csoonline.com/article/4149905/pypi-warns-developers-after-litellm-malware-found-stealing-cloud-and-ci-cd-credentials.html) and can be installed through an ordinary “pip install unsloth” without selecting a beta or prerelease version.\n\nUnsloth uses Hugging Face’s [trust_remote-code](https://www.csoonline.com/article/4181094/hugging-face-transformers-rce-flaw-enables-stealthy-compromise-via-ai-model-configs.html?utm=hybrid_search#:~:text=trust_remote_code=false) option, which allows a model to bring along its own Python code when needed.\n\nThat’s not necessarily dangerous by itself. Some legitimate Hugging Face models, including IBM Granite Speech and Vision, DeepSeek-OCR, ChatGLM, and earlier Qwen releases, need custom code to work properly, Fogel said.\n\nThe problem was that Unsloth enabled the feature automatically during a routine model check rather than requiring the user to explicitly opt into running remote code. Before the patch, “trust_remote_code” was turned on by default when Unsloth used Hugging Face’s Transformers model-loading functionality to obtain information about a model being inspected.\n\nUnsloth’s maintainers also pointed to Hugging Face’s own malware scanning and warnings for models containing custom code as another reason for not treating the issue as a vulnerability. Pillar counters that Hugging Face’s protections are mostly blocklists and that its proof-of-concept (PoC) code was not flagged when scanned but could have fetched a malicious second-stage payload only when processed by Unsloth.\n\nHowever, Fogel stressed that this is not a [Hugging Face](https://www.csoonline.com/article/4201361/hugging-face-breach-shows-why-incident-response-needs-a-multi-model-ai-strategy.html) vulnerability, but an issue with how Unsloth uses trust_remote_code.\n\n[The fix went beyond flipping the setting. Pillar initially recommended pinning trust_remote_code=False on the model-checking path because that path only needed to read declarative information from config.json. Unsloth’s eventual fix went further.]\n\nIn version 2026.6.9, Studio was changed to no longer enable arbitrary model loading directly from Hugging Face and to not trust remote code from local model files. Fogel said it independently retested the version and confirmed that both the Hugging Face and local-directory attack paths were closed.\n\nPillar urged users to upgrade to the fixed version, even if they never launch Studio and only use Unsloth core. Additionally, the company advised to audit LLM workflows for unnecessary occurrences of trust_remote_code=True.\n\n“The time-to-exploit for attackers keeps shrinking, because automated repo scanning, agentic exploitation, and organized supply-chain campaigns can weaponize a benign-looking auto_map module even faster than before the adoption of AI,” Fogel warned.\n\n*This article first appeared on* [InfoWorld](https://www.infoworld.com/article/4228904/unsloths-model-picker-had-a-code-execution-problem.html)*.*", "url": "https://wpnews.pro/news/unsloths-model-picker-had-a-code-execution-problem", "canonical_source": "https://www.csoonline.com/article/4228910/unsloths-model-picker-had-a-code-execution-problem-2.html", "published_at": "2026-09-30 13:56:13+00:00", "updated_at": "2026-09-30 14:16:39.837354+00:00", "lang": "en", "topics": ["ai-safety", "ai-tools", "developer-tools", "ai-infrastructure"], "entities": ["Unsloth", "Unsloth Studio", "Pillar Security", "Ariel Fogel", "Hugging Face", "PyPI", "IBM Granite Speech and Vision", "DeepSeek-OCR"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/unsloths-model-picker-had-a-code-execution-problem", "markdown": "https://wpnews.pro/news/unsloths-model-picker-had-a-code-execution-problem.md", "text": "https://wpnews.pro/news/unsloths-model-picker-had-a-code-execution-problem.txt", "jsonld": "https://wpnews.pro/news/unsloths-model-picker-had-a-code-execution-problem.jsonld"}}